Skip to content

Retaining Medical Payment Records

Question: 
Can we store digital copies of medical payments processed through a lockbox to meet record retention requirements for HIPPA or do original physical documents need to be kept? We are using the 10 yr retention schedule currently; assume that is correct?
Answer: 
Answer: 

by John Burnett:

From that source:

"[T]he HIPAA Privacy Rule does not include medical record retention requirements. Rather, State laws generally govern how long medical records are to be retained. However, the HIPAA Privacy Rule does require that covered entities apply appropriate administrative, technical, and physical safeguards to protect the privacy of medical records and other protected health information (PHI) for whatever period such information is maintained by a covered entity, including through disposal. See 45 CFR 164.530(c)."

First published on 09/17/2023

Filed under: 
Filed under operations as: 

Search Topics